Vulnerabilities
Summary — last 7 days
New vulnerabilities2,568▼ 304 vs. last week
Critical / high1,352▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
68 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. | |
| Deferred | High (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. | |
| Deferred | High (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. | |
| Deferred | Critical (9.8) | 0.32% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. | |
| Deferred | Critical (9.8) | 0.32% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. | |
| Deferred | Medium (6.5) | 0.36% | — | Javier Casares WpvulnerabilityAI | 3/25/2026 | 6/17/2026 | Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPVulnerability: from n/a through <= 4.2.1. | |
| Deferred | Medium (6.5) | 0.13% | — | Wpsight WpcasaAI | 3/19/2026 | 6/17/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue affects WPCasa: from n/a through 1.4.1. | |
| Deferred | High (8.1) | 0.58% | — | Ancorathemes CasamiaAI | 3/5/2026 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental Real Estate WordPress Theme casamia allows PHP Local File Inclusion.This issue affects CasaMia | Property Rental Real Estate WordPress Theme: from n/a through… | |
| Analyzed | Medium (6.9) | 0.68% | — | Icewhale Casaos | 1/2/2026 | 9/30/2026 | CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which… | |
| Deferred | Critical (9.8) | 0.82% | — | WpcasaAI | 9/23/2025 | 6/17/2026 | The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code. | |
| Deferred | Medium (6.5) | 0.32% | — | Wpsight WpcasaAI | 4/16/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa wpcasa allows Stored XSS.This issue affects WPCasa: from n/a through <= 1.3.2. | |
| Deferred | Medium (5.3) | 0.37% | — | Wpsight WpcasaAI | 12/6/2024 | 6/17/2026 | Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPCasa: from n/a through <= 1.2.13. | |
| Modified | Medium (5.4) | 0.24% | — | Miloco Postcasa Shortcode | 11/11/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miloandrew Postcasa Shortcode postcasa allows DOM-Based XSS.This issue affects Postcasa Shortcode: from n/a through <= 1.0. | |
| Deferred | Critical (9) | 0.29% | — | Casa Systems Ntc-221AI | 10/22/2024 | 6/17/2026 | An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component. | |
| Modified | Critical (9.8) | 0.77% | — | Alcasar | 6/13/2024 | 6/17/2026 | ALCASAR before 3.6.1 allows still_connected.php remote code execution. | |
| Modified | Critical (9.8) | 0.77% | — | Alcasar | 6/13/2024 | 6/17/2026 | ALCASAR before 3.6.1 allows email_registration_back.php remote code execution. | |
| Analyzed | Critical (9.6) | 0.35% | — | Alcasar | 6/13/2024 | 6/17/2026 | ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php. | |
| Deferred | Critical (9.8) | 0.71% | — | Casap Automated Enrollment SystemAIPHPAIMysqliAI | 5/14/2024 | 6/17/2026 | SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component | |
| Deferred | High (8) | 0.72% | — | Casa Systems Nl1901acvAI | 5/2/2024 | 6/17/2026 | An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function. | |
| Analyzed | High (7.5) | 0.62% | — | Icewhale Casaos-userservice | 4/1/2024 | 6/17/2026 | Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet… | |
| Analyzed | High (7.5) | 0.76% | — | Icewhale Casaos-userservice | 3/6/2024 | 6/17/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is… | |
| Analyzed | Critical (9.8) | 0.98% | — | Icewhale Casaos | 3/6/2024 | 6/17/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability… | |
| Analyzed | Critical (9.8) | 0.97% | — | Icewhale Casaos | 3/6/2024 | 6/17/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly… | |
| Modified | High (8.8) | 1.6% | — | Icewhale Casaos | 8/24/2023 | 6/17/2026 | CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue. | |
| Analyzed | Critical (9.8) | 6.8% | — | Icewhale Casaos | 7/17/2023 | 6/17/2026 | CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part… |